All of lore.kernel.org
 help / color / mirror / Atom feed
* split admins
@ 2002-04-24 13:45 Tom
  2002-04-24 13:59 ` Stephen Smalley
  2002-04-24 14:09 ` Stephen Smalley
  0 siblings, 2 replies; 4+ messages in thread
From: Tom @ 2002-04-24 13:45 UTC (permalink / raw)
  To: SE Linux

Policy Question:

I've tried setting up a seperate "security admin" role, as a 1st step
towards a split admin concept. Idea being that sysadm_r can not change the
SELinux policy (obviously I'll have to think about "circumvention" ways
like access to lilo, raw devices, etc. later), but a new role,
secadm_r, has control over these areas.

one problem I encountered was that newrole -r secadm_r didn't work,
kicking me out with:
arkham:~# newrole -r secadm_r
Couldn't get default type.

So where do I set this default type? I didn't find anything obvious,
and actually, I believed that my modification of domains/admin.te,
which included role secadm_r type secadm_t would've taken care of that.


If anyone's done something like this (splitting root into several
segments) before, any hints would be appreciated.


-- 
http://web.lemuria.org/pubkey.html
pub  1024D/D88D35A6 2001-11-14 Tom Vogt <tom@lemuria.org>
     Key fingerprint = 276B B7BB E4D8 FCCE DB8F  F965 310B 811A D88D 35A6

--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2002-04-24 14:27 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-04-24 13:45 split admins Tom
2002-04-24 13:59 ` Stephen Smalley
2002-04-24 14:28   ` Tom
2002-04-24 14:09 ` Stephen Smalley

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.